How Should Organizations Secure Unpatchable Legacy Systems?

An organization disabled unneeded services and placed a firewall in front of a business-critical legacy system. Which of the following best describes the actions taken by the organization?

  1. Exception
  2. Segmentation
  3. Risk transfer
  4. Compensating controls Source Reference Answer

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

It tests the distinction between native security hardening and alternative risk mitigation strategies, with candidates frequently confusing the tactical use of firewalls for strategic risk control.

This question evaluates how teams mitigate vulnerabilities in outdated infrastructure when standard patching is impossible. The community consensus firmly identifies these measures as compensating controls.

Candidates typically choose Segmentation because they fixate on the firewall's isolation function, failing to recognize that the overarching goal is compensating for the legacy system's inability to meet modern security standards.

Community Discussion (11 comments)

Th3irdEye 👍 10 Selected: D
The word "legacy" should inform that this action is compensating.
Etc_Shadow28000 👍 8 Selected: D
D. Compensating controls The actions taken by the organization—disabling unneeded services and placing a firewall in front of a business-critical legacy system—are examples of compensating controls. Compensating controls are security measures that are implemented to mitigate risk when the primary controls are not feasible or sufficient. In this case, since the legacy system might have inherent vulnerabilities that cannot be fully addressed, the organization has implemented additional controls to reduce the risk. Therefore, the correct answer is: D. Compensating controls
EngAbood 👍 1 Selected: D
Legacy = Compensating
G3O 👍 1 Selected: D
By implementing compensating controls (disabling unneeded services and using a firewall), the organization is mitigating the risks associated with the legacy system in the absence of being able to fully secure it through traditional means.
deejay2 👍 1
Segmentation means seperate, you're not seperating anything. You're disabling one thing and inputting something else to implement additional security. D is correct.
dbrowndiver 👍 2 Selected: D
Compensating controls is the best choice because the actions taken by the organization are intended to mitigate the risks associated with a legacy system when more standard security measures cannot be applied. By implementing these alternative controls, the organization effectively enhances the security of the legacy system without requiring direct updates or changes to its structure.
CyberPark17 👍 1 Selected: B
best describes the "actions taken"?? Segmentation is the action taken by the organisation to have Compensating controls. B is the corect answer. Hope that helps.
networkmen 👍 1 Selected: D
It is a business critical legacy system - i would go with D Dompensationg controls
johnsongr8 👍 2
The actions taken by the organization best describe D. Compensating controls. These measures are implemented to mitigate potential risks associated with the legacy system, ensuring its security despite inherent vulnerabilities.
SHADTECH123 👍 1 Selected: D
Compensating controls are alternative measures implemented to mitigate the risk of a vulnerability when the primary controls cannot be applied. In this scenario, the organization has: Disabled unneeded services: This reduces the attack surface of the legacy system, limiting potential vulnerabilities. Placed a firewall in front of the system: This provides an additional layer of security, controlling and monitoring the traffic to and from the legacy system.
whatsupdeepak 👍 1
D - Compensating controls

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Understanding Compensating Controls

Compensating controls are alternative security measures implemented when primary controls (such as software updates, vendor patches, or native feature configurations) are unavailable, impractical, or too costly. In this scenario, the organization is dealing with a business-critical legacy system, which inherently lacks modern security architectures or patch support.

Why Option D is Correct

Disabling unneeded services directly reduces the attack surface, while placing a firewall in front of the system creates a hardened perimeter. As noted by multiple community members, the keyword 'legacy' signals that traditional remediation isn't feasible, making these technical adjustments classic examples of compensating controls designed to maintain operational continuity without compromising security posture. Community feedback consistently highlights that when a system cannot be natively secured, alternative controls become mandatory.

Why Other Options Are Incorrect

  • Exception: Refers to a formal policy waiver granted for a specific user or system, not a technical hardening action.
  • Segmentation: While firewalls can enforce network segmentation, the question emphasizes risk mitigation for an unpatchable asset. Segmenting is a technique; compensating controls describe the overarching risk management strategy. Several users debated this, but the primary objective aligns with compensation rather than pure network architecture design.
  • Risk Transfer: Involves shifting financial or legal liability to a third party (e.g., cyber insurance or cloud SLAs), which does not apply to internal hardening steps.

Exam Takeaway

Always map the scenario's constraint (legacy/unpatchable) to the appropriate risk treatment framework before selecting the technical mechanism.

Official Reference

Exam Strategy

When a question highlights outdated, unsupported, or unpatchable systems, prioritize compensating controls over native security features. Always analyze the root problem first (inherent vulnerability) before selecting the tactical solution (firewall/service reduction), as CompTIA frequently tests the distinction between implementation methods and risk management objectives.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide